Vulnerability Details CVE-2021-43307
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Exploit prediction scoring system (EPSS) score
EPSS Score 0.031
EPSS Ranking 86.2%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 5.0
Products affected by CVE-2021-43307
-
cpe:2.3:a:semver-regex_project:semver-regex:0.1.0
-
cpe:2.3:a:semver-regex_project:semver-regex:0.1.1
-
cpe:2.3:a:semver-regex_project:semver-regex:1.0.0
-
cpe:2.3:a:semver-regex_project:semver-regex:2.0.0
-
cpe:2.3:a:semver-regex_project:semver-regex:3.0.0
-
cpe:2.3:a:semver-regex_project:semver-regex:3.1.1
-
cpe:2.3:a:semver-regex_project:semver-regex:3.1.2
-
cpe:2.3:a:semver-regex_project:semver-regex:3.1.3
-
cpe:2.3:a:semver-regex_project:semver-regex:4.0.0
-
cpe:2.3:a:semver-regex_project:semver-regex:4.0.1
-
cpe:2.3:a:semver-regex_project:semver-regex:4.0.2